CVE-2022-43451: Multiple path traversal in appspawn and nwebspawn services.
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43451?
CVE-2022-43451 refers to a multiple path traversal vulnerability in OpenHarmony-v3.1.2 and prior versions.
How severe is CVE-2022-43451?
CVE-2022-43451 has a severity rating of 6.5 (High).
What is the impact of CVE-2022-43451?
CVE-2022-43451 allows local attackers to create arbitrary directories or escape application sandbox, potentially leading to unauthorized access and privilege escalation.
How can I mitigate CVE-2022-43451?
To mitigate CVE-2022-43451, it is recommended to update OpenHarmony to version 3.1.2 or later.
Where can I find more information about CVE-2022-43451?
You can find more information about CVE-2022-43451 at the following reference: [link](https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-11.md)